Visitors Right Now Counter Security & Risk Analysis

wordpress.org/plugins/visitors-right-now-uk

Shows the number of users on the site

0 active installs v1.3.1 PHP + WP 4.0+ Updated Aug 26, 2020
count-visitorscount-website-visitorsvisitor-countervisitorsvisitors-right-now
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Visitors Right Now Counter Safe to Use in 2026?

Generally Safe

Score 85/100

Visitors Right Now Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "visitors-right-now-uk" plugin v1.3.1 exhibits a generally good security posture, with no known vulnerabilities in its history and a relatively small attack surface. However, the static analysis reveals several areas of concern that temper this positive outlook. The low percentage of properly escaped output (36%) and the absence of any capability checks or nonce checks are significant weaknesses. This combination suggests that user-supplied data, particularly if it reaches the single shortcode entry point, could be vulnerable to cross-site scripting (XSS) attacks if not properly handled within the plugin's logic. While the majority of SQL queries utilize prepared statements, the presence of raw SQL queries still introduces a minor risk of SQL injection if those specific queries are not adequately sanitized.

The plugin's clean vulnerability history is a positive indicator, suggesting developers have a history of addressing security issues. However, the static analysis findings regarding output escaping and lack of authorization checks are critical indicators that should not be overlooked. The absence of taint analysis results is also noteworthy, though it could simply mean no complex data flows were detected or the analysis tools had limitations. In conclusion, while the plugin avoids common pitfalls like unpatched CVEs, the identified code-level weaknesses in output sanitization and authorization present a tangible risk that requires attention.

Key Concerns

  • Unescaped output (64% not properly escaped)
  • No nonce checks
  • No capability checks
  • Raw SQL queries present (43% not prepared)
Vulnerabilities
None known

Visitors Right Now Counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Visitors Right Now Counter Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
4 prepared
Unescaped Output
14
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
10
External Requests
0
Bundled Libraries
0

SQL Query Safety

57% prepared7 total queries

Output Escaping

36% escaped22 total outputs
Attack Surface

Visitors Right Now Counter Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[visitors] classes\class.visitors.php:39
WordPress Hooks 11
filterplugin_row_metaclasses\class.visitors.php:31
actionadmin_menuclasses\class.visitors.php:33
actionwp_enqueue_scriptsclasses\class.visitors.php:35
actionadmin_enqueue_scriptsclasses\class.visitors.php:37
actionwp_loadedclasses\class.visitors.php:41
actioninitvisitors-right-now.php:48
actionwidgets_initvisitors-right-now.php:50
actionget_footervisitors-right-now.php:58
actionwp_enqueue_scriptsvisitors-right-now.php:76
actionadmin_enqueue_scriptsvisitors-right-now.php:77
filterscript_loader_tagvisitors-right-now.php:85
Maintenance & Trust

Visitors Right Now Counter Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 26, 2020
PHP min version
Downloads957

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Visitors Right Now Counter Developer Profile

visitorsrightnowplugin

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Visitors Right Now Counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/visitors-right-now-uk/assets/css/custom-frontend.css/wp-content/plugins/visitors-right-now-uk/assets/css/custom-backend.css/wp-content/plugins/visitors-right-now-uk/assets/js/prefixfree.min.js/wp-content/plugins/visitors-right-now-uk/assets/js/tinycolor.min.js/wp-content/plugins/visitors-right-now-uk/assets/js/index.js
Script Paths
//cdn.visitorsrightnow.co.uk/
Version Parameters
visitors-right-now-uk/assets/css/custom-frontend.css?ver=visitors-right-now-uk/assets/css/custom-backend.css?ver=visitors-right-now-uk/assets/js/prefixfree.min.js?ver=visitors-right-now-uk/assets/js/tinycolor.min.js?ver=visitors-right-now-uk/assets/js/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
wvrnp-visitors-right-now
Data Attributes
data-wvrnp-id
JS Globals
WVRNP_Visitors
Shortcode Output
[visitors]
FAQ

Frequently Asked Questions about Visitors Right Now Counter